SB2019120431 - Multiple vulnerabilities in Keycloak
Published: December 4, 2019 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Improper Authentication (CVE-ID: CVE-2019-14910)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication succeeds even if invalid password has entered.
2) Improper Authentication (CVE-ID: CVE-2019-14909)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.
Remediation
Install update from vendor's website.